How are you addressing ransomware at your organization?
I think everybody has to give up on the single pane of glass. I've been wanting that for 20 years, and it's a myth. It's never going to happen.
It's a myth.
We were trying to do that at Armis. So when I was at Armis, we basically API-ed and integrated with every security product out there, so we'd be pulling data from every single security product you already have into our tool so that you could use it as an investigation platform, you could see exactly where the alerts were coming from. It was pretty interesting how they did it.
While there’s no one-size-fits-all approach to this, but I would like to think you could have 1 incident management policy with individual incident management procedures. Depending on the type of incident, your CART team is going to change. If it is a data breach, there's more involvement with legal, marketing and communications teams. If it is ransomware, it's heavier on your IT and tech operations teams—of course there is still an element involving legal and cyber insurance, etc. Now that US laws have been able to stricten around that, there’s also a law enforcement component to it. You would have multiple specific incident response procedures governed by the same policy and the same training that you launch across the organization.
1, invest and automate the basic security programs of patching, setting recovery priorities and acceptable limits, backing up, testing recoveries, and incident response
2. invest and establish visibility of security posture of the enterprise by using micro segmentation, going inside out and by integrating security incidents and event assessments into incident response playbooks and runbooks
3. invest, train and exercise the ability top leadership on how to handle a ransomware induced business crisis by preparing payment systems, using insurance, forensic analysts and negotiators when needed to ensure business continuity
Content you might like
Follow up to my previous travel question… What is your favorite place to travel to for work and why?
SANS Cyber Security Leadership NOVA10%
ENISA Cybersecurity Standardisation Conference 202343%
Gartner Security & Risk Management Summit13%
SANS Cyber Security East (Feb edition)3%
Nope30%
Yes54%
No, but I plan to36%
No, and I do not plan to10%